CVE-2025-62654: Stored XSS through system messages in QuizGame
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki QuizGame extension allows Stored XSS.This issue affects MediaWiki QuizGame extension: 1.39, 1.43, 1.44.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62654?
CVE-2025-62654 is considered a high severity vulnerability due to the potential for stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-62654?
To fix CVE-2025-62654, upgrade the MediaWiki QuizGame extension to version 1.45 or later.
Which versions of MediaWiki QuizGame extension are affected by CVE-2025-62654?
CVE-2025-62654 affects MediaWiki QuizGame extension versions 1.39 through 1.44.
What type of vulnerability is CVE-2025-62654?
CVE-2025-62654 is classified as an Improper Neutralization of Input During Web Page Generation vulnerability, specifically facilitating stored XSS.
Who is responsible for addressing CVE-2025-62654?
The Wikimedia Foundation is responsible for addressing CVE-2025-62654 in their MediaWiki QuizGame extension.